Antivirus XP 2008 - Newest Malware On The Internet

87
rate this page

By mattd241


Just so you're all aware there is a new malware being spread out on the net. I got hit with it earlier today visiting what looked like a legitimate video site.

It's called "Antivirus XP 2008" and is attached to a download of a codec pack that you are told is needed to view a video or picture.

(It may also be attached in a message that you need an ActiveX update)

It actually plants a constant image on a blue desktop (you lose your desktop image, if you have one) and a constant pop-up generates, telling you that a virus has been detected and directs you to a very good replica of a microsoft page that wants $50 - $100 for the Antivirus XP 2008 cure (depending on the package you purchase). It is a POS and also has to be removed.

Luckily, I figured it out before buying, but it still took me 4 hours to clean my folders, files, and registries. I also had to create a new registry to get back my screensaver and desktop background option tabs.

Below are some basic instructions for manually removing this malware. Please read carefully and perform at your own risk!

First you need to stop the program from loading on startup. This is what you do to stop it:

Click "Start," then, "run"

Type: msconfig

Go to Startup tab

Uncheck lphc35dj0e1an <----- These number/letters may be different

Uncheck rhc75dj0e1an <------- but will be similar to each other. Usually two that are very similar. These were taken from my computer.

Click: apply

Sponsored Links

  • NOSTALGIA FINDER Remember what Mom threw away when you "grew up"? Wish you had it now? Now you can find it!
  • SEARCH BEACON More than a search engine. Dating, Horoscopes, Shopping, and much more available!
  • MILITARY INFO Find out what is happening around the world from military sources.
  • EDUCATION INFO Need the top resources on Education? This site has it.
  • CREDIT REPAIR The best site for fixing your credit reports and credit problems FAST!
  • COMPUTERS A great resource for new and used computers, laptops, and even vintage equipment.
  • iPHONES Need one? This site has a highly filtered search giving you just the phones without those who offer the unwanted codes.

Stop XP Antivirus 2008 Processes:

Access Processes by pressing Cont+Alt+Delete simultaneously (1 time)

(All below may or may not be present - stop any found)

vav.exe

XPAntivirus.exe

XPAntivirusUpdate.exe

xpa.exe

xpa2008.exe

Click: OK

Restart computer

Then you need to delete the main files this program uses. Delete the following files.

C:\windows\system32\lphc35dj0e1an.exe <------ Again, your .exe may be different than these!

C:\program files\rhc75dj0e1an\rhc75dj0e1an.exe

Also, do not forget to do a file and folder search...

Find and Delete these XP Antivirus 2008:

(may or may not be present)

xpa.exe

vav.exe

xpa2008.exe

XPAntivirus.exe

XPAntivirusUpdate.exe

XP antivirus

XPAntivirus.lnk

Uninstall XPAntivirus.lnk

XPAntivirus on the Web.lnk

XPAntivirus.url

XP Antivirus 2008.lnk

Uninstall XP Antivirus 2008.lnk

This should remove the program from your system but you probably still have a warning message displayed as your wallpaper in Windows and the virus removed the ability to change the wallpaper or your desktop settings.

To restore ability to change your desktop settings and select a different wallpaper and screen saver do the following:

Click: Start->Run->type: regedit ->click "OK"

Open the following folders\subfolders in order:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\

CurrentVersion\Policies\System

“System” being the last sub-folder.

create new entries:

1) a REG_DWORD entry called: NoDispBackgroundPage

2) a REG_DWORD entry called: NoDispScrSavPage

As long as their values are both set to 0, your tabs will be back.

Restart Computer

- Are you Tweaked, Twisted, or Torqued over what's happening around us? Join this brand new forum today! The Tweak Show

Comments

RSS for comments on this Hub Small RSS Icon

Michelle  says:
2 months ago

Sorry to hear you got hit by this, and thank you for the information, I am running XP. There are many times in the past I have been hit by viruses that have crashed my entire system, it was hell to rebuild the system and reinstall all of my software.

Wouldn't you love to have a baseball bat and a few minutes alone in a room with the &$$#*!% that created that virus! You could discuss baseball statistics or something....

mattd241 profile image

mattd241  says:
2 months ago

Hi Michelle,

I'd like to see the maker of this do some jail time. There must be law against it and the developer is obviosly profiting from the sale of the AV program. Jail time after I'm done giving him those baseball statistics with the bat, of course. :)

A forum friend also informed me it is also being spread by use of a message stating an ActiveX control is needed to be installed.

I'm aware that many people resort to wiping out an entire hard drive to remove this and other viruses. I'm hoping with this info, that won't be necessary. Doing a google search of "Antivirus XP 2008" will bring up sites that also explain how to manually uninstall this malware. Luckily, this is one that still gives you the ability to use the internet - though painstaking slowly.

RyzER  says:
5 weeks ago

HOLY SHIT THIS WORKED PERFECTLY!!!!!!!!1

cound'nt get my tabs back for desktop---added the reg values--then BANG!!--Didnt even have to RESTART---I just logged off/back on--!

THANK YOU HOMEBOY!!!!!!!!!!!!

PC  says:
5 weeks ago

Many thanks Bud! Ur method worked first time. Sorry I didnt find your assistance sooner!

mattd241 profile image

mattd241  says:
4 weeks ago

Glad it worked for you both. :)

mukhi  says:
4 weeks ago

by far the best instructions for removal of antivirus xp 2008. my ISS (webroot) could not detect or eliminate the virus, however, this manual process did it all. you rock! thanks a ton.

NickerT  says:
4 weeks ago

Worked like a Charm. Thanks G! Highly recommended. I'd put ya up for computer Wiz of the Year any day.

Don't let the New World Order Form, don't fall for satans 666 (the Vchip) or allow the North American Union to furrther form. Abolish the Amero and Praise God almighty.

Thanks again

sharky  says:
4 weeks ago

hi and thanks a lot ... had the same shitty xp , very good help to solve

Steve  says:
4 weeks ago

Excellent advice. So far so good & the registry fix for the display & screensaver tabs worked perfect. Thanks for the post. It saved me a lot of time & suffering.

mattd241 profile image

mattd241  says:
3 weeks ago

Makes me feel all warm and fuzzy knowing one of my hubs is doing some good! :)

Jack  says:
4 days ago

I am from Singapore. I got hit by the same Malware 2 weeks ago. Could not solve the problem till I stumbled on to your website.

I did according to your approach and got rid of the "shit".

All I can say is 'THANK YOU.........."

Submit a Comment

Members and Guests

Sign in or sign up and post using a hubpages account.


optional



working